logo

Megalodon Campaign Backdoors GitHub Repositories via CI Workflow Compromise (Campaign)

ID: d11ed007-c46b-517b-a562-cf12ced03d81

STIX ID: report--d11ed007-c46b-517b-a562-cf12ced03d81

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2026-05-22

Date Updated: 2026-05-29

Author: [email protected] (Wiz Threat Research)

...
...

Megalodon is a large-scale software supply-chain campaign that compromised thousands (~5,500) GitHub repositories by injecting malicious GitHub Actions workflows which exfiltrated CI/CD secrets, cloud credentials, SSH keys, OIDC tokens, Kubernetes and Terraform credentials, and also poisoned npm package releases; attackers used forged CI identities and likely leveraged compromised personal access tokens or deploy keys, employing both auto-executing workflows and dormant workflow_dispatch backdoors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.